VYPR
Medium severity4.3NVD Advisory· Published Nov 21, 2025· Updated Apr 27, 2026

CVE-2025-66075

CVE-2025-66075

Description

Missing Authorization vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent gdpr-cookie-consent allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/a through <= 4.0.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in WP Cookie Notice plugin <=4.0.3 allows unprivileged attackers to exploit broken access controls, potentially altering site configuration.

Root

Cause The WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin (versions up to 4.0.3) contains a missing authorization vulnerability [1]. The plugin fails to properly verify access control permissions, allowing exploited incorrectly configured access control security levels. This is classified as a Broken Access Control issue [1].

Exploitation

Attackers can exploit this flaw remotely without prior authentication, as the missing authorization check allows unprivileged users to execute functions that should be restricted to higher-privileged roles [1]. The vulnerability is reportedly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of size [1].

Impact

The severity is rated as Medium (CVSS 4.3) but the Patchstack advisory notes a low severity impact within the WordPress context, deeming exploitation unlikely [1]. However, successful exploitation could allow attackers to perform actions that require administrative privileges, potentially compromising site configuration.

Mitigation

The vulnerability has been patched in version 4.0.4 [1]. Users are strongly advised to update immediately. Patchstack subscribers can enable auto-updates for the plugin to stay protected [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.